Files
2nd/10_Wiki/Topic_Programming/Architecture/Complex Event Processing (CEP).md
T
Antigravity Agent 9148c358d0 docs(10_Wiki): 위키 전체 재구성 — Topic_* 폴더를 4개 카테고리로 통합 + 대규모 중복 제거
Topic_Agent/Topic_Blog/Topics/Topics_Biz/Topics_Meeting/Topics_Rag의 마크다운 지식 문서를
Topic_General/Topic_Programming/Topic_Graphic/Topic_Business 4개 카테고리로 재분류.

- 중복 제거: frontmatter의 status:duplicate/merged + duplicate_of/redirect_to 필드로
  자기 자신을 중복으로 선언한 리다이렉트 stub 1032개 제거, 완전 동일 내용 파일 472개 제거,
  동일 파일명·다른 내용 충돌 시 더 큰(완전한) 버전만 유지(162개 제거) — 총 1639개 중복 제거.
- 분류: 폴더 단위로 명확한 항목(AI_and_ML/Coding/Architecture 등 → Programming,
  Comfyui/Visual_Effects → Graphic, Topics_Biz/Topics_Meeting/사업 등 → Business,
  Poetic_Blog_Writing/창의성/Game_Design 등 → General)은 폴더 우선순위로,
  나머지 혼재 폴더(Topic_Agent/Topic_Blog/Topics 루트/Thinking & Reasoning/Other/UI_UX_Assets)는
  title/tags 키워드 스코어링으로 파일 단위 분류(불명확한 경우 General로 폴백).
  원본 폴더명은 "From_*" 서브폴더로 보존해 추적 가능성 유지.
- 최종 배치: Programming 2784 / General 1608 / Graphic 285 / Business 249 = 4926개 문서.
- 에이전트 운영 상태(.astra/.agent/.obsidian/sessions/memory/_company/docs/lessons/_shared/src)는
  지식 콘텐츠가 아니므로 재분류 대상에서 제외하고 원위치 유지.
- Topics/Topic_email(상위 보호 폴더 Topic_email과 파일명 100% 중복) 삭제 — 보호 폴더 자체는 미변경.
- 완전히 비게 된 Topic_Agent/Topic_Blog/Topics_Biz/Topics_Rag 폴더 제거.
2026-07-05 00:33:48 +09:00

4.6 KiB

id, title, category, status, canonical_id, aliases, duplicate_of, source_trust_level, confidence_score, verification_status, tags, raw_sources, last_reinforced, github_commit, tech_stack
id title category status canonical_id aliases duplicate_of source_trust_level confidence_score verification_status tags raw_sources last_reinforced github_commit tech_stack
wiki-2026-0508-complex-event-processing-cep Complex Event Processing (CEP) 10_Wiki/Topics verified self
CEP
Event Stream Processing
복합 이벤트 처리
none A 0.88 applied
cep
streaming
event-driven
flink
esper
2026-05-10 pending
language framework
java flink

Complex Event Processing (CEP)

매 한 줄

"매 stream of simple events → meaningful complex pattern". David Luckham (Stanford, 2002) 가 정의한 paradigm. 2026 현재 Apache Flink CEP, Kafka Streams, Esper NEsper 가 main implementation; fraud detection, IoT anomaly, algorithmic trading 의 backbone.

매 핵심

매 개념

  • Event: timestamped 의 fact (transaction, sensor reading, click).
  • Pattern: temporal/causal relationship 의 events (A followed by B within 5s).
  • Window: sliding/tumbling/session 시간 frame.
  • Aggregation: count, sum, avg over window.
  • Correlation: 다중 stream 매 join (e.g., trades + market data).

매 pattern operator

  • Sequence: A → B → C (in order).
  • Conjunction: A AND B (any order, in window).
  • Negation: A NOT followed by B.
  • Iteration: A repeated N times.
  • Within: temporal constraint.

매 응용

  1. Fraud detection — card swipes 매 different countries within 1h.
  2. IoT — sensor reading exceeds threshold for 3 consecutive readings.
  3. Trading — bid/ask spread anomaly detection.
  4. Network security — port scan pattern (many SYN, few ACK).
  5. SLA monitoring — 5xx error rate spike correlated with deploy event.

💻 패턴

Pattern<LoginEvent, ?> failedLogins = Pattern
    .<LoginEvent>begin("first")
    .where(e -> !e.success)
    .next("second").where(e -> !e.success)
    .next("third").where(e -> !e.success)
    .within(Time.minutes(5));

CEP.pattern(loginStream.keyBy(e -> e.userId), failedLogins)
   .select(match -> new Alert(match.get("first").get(0).userId))
   .addSink(alertSink);

Esper EPL — fraud detection

-- swipe in different countries within 1 hour
SELECT a.cardId, a.country, b.country
FROM pattern [
    every a=Swipe -> b=Swipe(cardId=a.cardId, country!=a.country)
        where timer:within(1 hour)
];

Kafka Streams — sliding window aggregation

KStream<String, Click> clicks = builder.stream("clicks");

clicks.groupByKey()
      .windowedBy(SlidingWindows.ofTimeDifferenceWithNoGrace(Duration.ofMinutes(5)))
      .count()
      .filter((k, count) -> count > 1000)
      .toStream()
      .to("anomalies");
stream.keyBy(e -> e.userId)
      .window(EventTimeSessionWindows.withGap(Time.minutes(30)))
      .aggregate(new SessionStats())
      .addSink(...);

Pattern with negation (NO heartbeat in 30s)

Pattern.<HeartbeatEvent>begin("start")
    .notFollowedBy("missing")
    .where(e -> true)
    .within(Time.seconds(30));

Modern: Materialize / RisingWave (SQL-native streaming)

CREATE MATERIALIZED VIEW fraud_alerts AS
SELECT user_id, COUNT(*) as failed_count
FROM logins
WHERE success = false
  AND ts > NOW() - INTERVAL '5 minutes'
GROUP BY user_id
HAVING COUNT(*) >= 3;

매 결정 기준

상황 Approach
Java/JVM, complex patterns Flink CEP
Kafka-centric, simple aggregation Kafka Streams
SQL-first, low ops Materialize / RisingWave
In-process, low-volume Esper
Cloud-native, serverless AWS Kinesis Data Analytics

기본값: Flink CEP for complex patterns, Materialize for SQL-native streaming.

🔗 Graph

🤖 LLM 활용

언제: pattern definition 매 natural language → EPL/Flink translation, alert explanation. 언제 X: micro-second latency hot path (LLM 매 too slow).

안티패턴

  • Unbounded state: window 없이 group-by → memory blowup.
  • Wall-clock instead of event-time: out-of-order event 매 wrong result.
  • Pattern explosion: NFA state count 매 exponential, pattern 너무 복잡.
  • No watermark: late event 매 silently lost.

🧪 검증 / 중복

  • Verified (Luckham 2002 Power of Events, Apache Flink CEP docs 2026).
  • 신뢰도 A.

🕓 Changelog

날짜 변경
2026-05-08 Phase 1
2026-05-10 Manual cleanup — full content with Flink CEP, Esper, Materialize